Federal judge dismisses privacy lawsuit against Crypto.com over cookie tracking
A California court ended the proposed class action after ruling the plaintiffs could not show a concrete injury from the alleged tracking
Clicking “Disable All” on a cookie banner feels like a small act of digital self-defense. A federal judge has now ruled that two people who said Crypto.com ignored that click could not show they were actually harmed by it.
On October 7, 2026, a federal court in the Northern District of California dismissed a proposed class-action lawsuit against Foris DAX, Inc., the company that operates the Crypto.com platform. The court found the plaintiffs lacked the concrete injury required for Article III standing, which closed the case entirely.
What the plaintiffs alleged
The suit was brought by Jose Ortiz and Javier Hernandez, who filed it on October 17, 2025, under case number 3:25-cv-08950. Their central complaint was simple to describe and, as it turned out, hard to litigate.
According to the complaint, Crypto.com kept third-party tracking running even after visitors selected “Disable All” on the site’s cookie consent banner.
They claimed this conduct violated several privacy laws. The headliner was the California Invasion of Privacy Act, usually shortened to CIPA, a state statute that has become a favorite tool in lawsuits over how websites monitor their visitors.
The case did not survive in one piece for long. On May 22, 2026, Judge Edward M. Chen dismissed most of the claims in an interim ruling.
One claim got a temporary reprieve. Judge Chen allowed a CIPA pen-register claim to move forward, pending an amendment from the plaintiffs.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
A quick translation for anyone who does not spend weekends reading surveillance statutes: a pen register is a concept rooted in phone surveillance, describing tools that capture information about outgoing communications. Plaintiffs in tracking cases have tried to argue that certain website trackers function the same way.
That surviving claim was the last thread holding the case together. The October 7 ruling cut it, dismissing the lawsuit on the same core ground: no concrete injury, no standing.
Why standing sank the case
Article III of the US Constitution limits federal courts to hearing actual cases and controversies. In practice, that means a plaintiff has to show they suffered a real, concrete harm before a judge will weigh whether the defendant did anything wrong.
That framing explains why this ruling is narrower than it might first appear. A standing dismissal is about whether these plaintiffs could bring this claim in federal court, not about whether the tracking described in the complaint was acceptable.
The court reaffirmed that plaintiffs must demonstrate a tangible harm, and the outcome reflects a broader shift in how California has approached website-tracking cases since the Ninth Circuit’s 2025 decision in Popa v. Microsoft. The common thread across those cases is that alleging a privacy statute was violated is not, on its own, enough.
What this means for Crypto.com and the industry
For Crypto.com, the immediate result is straightforward. A proposed class action that had been hanging over the company for close to a year is over, and the exchange avoided a fight on the merits of its cookie practices.
For consumers, the practical takeaway is sobering. Cookie banners give users a choice, but this case shows how difficult it can be to enforce that choice in federal court when the alleged harm is the tracking itself rather than some downstream damage.
For the plaintiffs’ bar, the message is equally clear. Future website-tracking suits against crypto platforms, or anyone else, will likely need to lead with concrete injury rather than leaning on the language of privacy statutes.